← Back to search

CVE-2026-71278

9.8 CRITICALpublic exploit available

Published 2026-08-05 · Updated 2026-08-10

AI risk analysis

Summary
The vulnerability allows an attacker to create a 'calc rule' without authentication, leading to potential unauthorized access and manipulation of the system.
Exploitability
Exploitation is relatively easy as the endpoint is accessible without authentication. An attacker needs to craft and send a POST request to /calc-rule/create.
Blast radius
If exploited, the attacker could potentially manipulate critical calculations or rules, leading to significant operational disruptions or data corruption.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the '/calc-rule/create' endpoint or restrict access to it via authentication.
auth-bypasswebrce

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary field. This route does not take the AuthToken request guard used elsewhere in the application, making it reachable without authentication.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-94

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.